PT-2023-6230 · Samba+5 · Samba+5

Kirin Van Der Veer

·

Publicado

2023-10-10

·

Atualizado

2024-11-15

·

CVE-2023-42670

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Samba (affected versions not specified)
Description A flaw was found in Samba, making it susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intended for non-AD DC purposes can erroneously start and compete for the same unix domain sockets, leading to partial query responses from the AD DC. This issue can cause problems such as "The procedure number is out of range" when using tools like Active Directory Users. The vulnerability is related to incorrect resource release in the RPC server, allowing a remote attacker to disrupt AD DC services by exploiting this flaw.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Resource Release

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-6448
ALT-PU-2023-7794
ALT-PU-2024-12484
ALT-PU-2024-14683
AZL-31901
AZL-37028
BDU:2023-06939
CVE-2023-42670
DSA-5525-1
ECHO-9E4D-E76A-7140
OESA-2023-1756
OESA-2023-1757
OPENSUSE-SU-2023_4046-1
OPENSUSE-SU-2024:13332-1
SUSE-SU-2023:4046-1
USN-6425-1
USN-6425-2
USN-6425-3

Produtos afetados

Alt Linux
Linuxmint
Red Os
Samba
Suse
Ubuntu